> ## Documentation Index
> Fetch the complete documentation index at: https://docs.streamly.watch/llms.txt
> Use this file to discover all available pages before exploring further.

# Deploy (Vercel)

> Deploy Streamly to Vercel as a standard Next.js app - first-operator email/password bootstrap and production checklist.

Streamly’s default `pnpm run build` output is a standard Next.js app. Vercel is a supported Node host. This is **not** static hosting: operator login, APIs, and webhooks need the server runtime.

## 1 - Import the app

Create a Vercel project from the **`streamly/`** folder (the directory that contains `package.json`), not the outer CodeCanyon ZIP wrapper.

Build command: `pnpm run build` (or Vercel’s Next.js default).
Install command: `pnpm install`.

## 2 - Production environment variables

Set these in the Vercel project **Settings → Environment Variables** for Production. Keep secrets **server-only** - never prefix them with `NEXT_PUBLIC_`.

| Variable | Required | Notes |
| - | - | - |
| `NEXT_PUBLIC_APP_URL` | Yes | `https://your-domain` |
| `NEXT_PUBLIC_PLATFORM_HOST` | Yes | Host without scheme |
| `NEXT_PUBLIC_STREAMLY_API_BASE` | Yes | `{APP_URL}/api/v1` |
| `NEXT_PUBLIC_SUPABASE_URL` | Yes | Supabase project URL |
| `NEXT_PUBLIC_SUPABASE_ANON_KEY` | Yes | Anon key |
| `SUPABASE_SERVICE_ROLE_KEY` | Yes | Server-only |
| `TENANT_SECRETS_MASTER_KEY` | Yes | `openssl rand -base64 32` |
| `STREAMLY_CRON_SECRET` | Yes | Cron header secret |
| `STREAMLY_INITIAL_ADMIN_EMAIL` | Yes (first install) | First operator email. **Never** `NEXT_PUBLIC_…` |
| `STREAMLY_INITIAL_ADMIN_PASSWORD` | Yes (first install) | ≥ 16 characters. **Never** `NEXT_PUBLIC_…`. Removable after bootstrap |
| `RESEND_API_KEY` | Optional | Viewer email notifications |
| `STREAMLY_FROM_EMAIL` | Optional | Verified sender |
| `TMDB_API_TOKEN` | Recommended | Metadata import |

Full list: [Environment Variables](/technical/environment-variables).

Leave `ENABLE_DEMO` unset (or `false`) on Vercel production. It is only for the public CodeCanyon preview and permits shared demo credentials.

## 3 - First operator

1. Deploy the production URL.
2. Open `/admin/login`.
3. Sign in with **exactly** the bootstrap email and password.
4. After success, remove `STREAMLY_INITIAL_ADMIN_PASSWORD` from Vercel and redeploy. Later logins use Supabase Auth only.

`POST /api/admin/login` will not create or promote any other user after that first operator exists.

## 4 - After deploy

| Check | Expect |
| - | - |
| `/` | Storefront loads |
| `/admin/login` | Email + password form |
| First sign-in | Creates the operator and sets the operator cookie |
| Second deploy without the password env var | Existing operator can still sign in |

Optional: Vercel Cron can `POST /api/internal/jobs/run` with `X-Streamly-Cron-Secret`. See [Deploy (Node)](/getting-started/deploy-node) for job payloads.

The built-in login limit is per application instance. Add a Vercel Firewall rate-limit rule for `POST /api/admin/login` on a distributed production deployment.

## Related

* [Installation](/getting-started/installation)
* [Authentication Flow](/authentication/authentication-flow)
* [Environment Variables](/technical/environment-variables)
* [Security](/technical/security)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.